Re: BellaBook Admin Bypass/Remote Code Execution

看板Bugtraq作者時間18年前 (2007/08/13 14:38), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串2/2 (看更多)
As with your so-called bypass of BellaBiblio, this is not actually correct. You state that with the username you can gain access to the login page - but you seem to have missed the fact that the password and totally random salt are needed too? Furthermore, you're using a script designed to bypass pheap login features with a few modifications - that does nothing to my scripts.
文章代碼(AID): #16l_nG00 (Bugtraq)
文章代碼(AID): #16l_nG00 (Bugtraq)